Courseiva

AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel

You are designing a Microsoft Sentinel solution for a multinational company. The company requires that security incidents be correlated across regions, but data residency mandates require logs to remain in their original region. What should you implement?

⚠ Common exam trap

Candidates often assume a single Sentinel workspace is required for centralized correlation, overlooking that cross-workspace querying can achieve the same goal while respecting data residency mandates.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Deploy one Microsoft Sentinel workspace per region and use cross-workspace querying for correlation

Deploying one Microsoft Sentinel workspace per region satisfies data residency mandates by keeping logs in their original region, while cross-workspace querying allows security incidents to be correlated across regions using KQL queries that span multiple workspaces. This approach ensures compliance with regional data sovereignty laws without sacrificing the ability to perform centralized threat detection and investigation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Deploy one Microsoft Sentinel workspace per region and use cross-workspace querying for correlation

    Why this is correct

    Deploying one Microsoft Sentinel workspace per region satisfies data residency because each workspace is a Log Analytics workspace that ingests and stores logs within its own geographic boundary. Cross-workspace querying with the 'workspace()' expression or Azure Resource Graph lets security analysts run a single KQL query that references multiple workspaces, correlating threats without moving data out of its resident region. Sentinel's built-in UEBA and analytics rules work on each workspace, while cross-workspace views preserve centralized hunting.

  • ✗

    Deploy a separate Log Analytics workspace per region, but only one Sentinel workspace

    Why it's wrong here

    Microsoft Sentinel is enabled on an existing Log Analytics workspace, so each Log Analytics workspace needs its own Sentinel deployment; you cannot have one Sentinel workspace that manages multiple Log Analytics workspaces as a single entity. A separate Log Analytics workspace per region without per-region Sentinel means that each region lacks its own Sentinel resources, like analytics rules and automation, forcing you to configure them per workspace or forgo residency-aligned detection. This architecture creates management overhead and fails to provide a single security operations plane as required in the question.

  • ✗

    Deploy a single Microsoft Sentinel workspace in a central region and use Azure Lighthouse

    Why it's wrong here

    A single Sentinel workspace in a central region forces all log data to be stored in that workspace's Log Analytics instance, directly violating the stated data residency requirement that logs remain in their region of origin. Azure Lighthouse provides cross-tenant and cross-subscription governance through delegated access, but it does not alter where telemetry resides, nor does it create geo-replicated storage for logs. Without a workspace in each region, you cannot enforce residency, even if you use Lighthouse to centrally view the workspace.

  • ✗

    Deploy a single Microsoft Sentinel workspace and use data collection rules to filter logs

    Why it's wrong here

    Data collection rules (DCRs) control which data is ingested, such as filtering log categories from an agent, but they do not change the storage location of the data that is actually collected—everything still lands in the single central workspace. If the DCR filters out data to reduce residency risk, you lose necessary security logs, which is unacceptable for a Sentinel solution. Log Analytics workspaces are single-region services, so a single workspace with DCRs cannot magically partition or geo-distribute storage; residency remains broken.

About these practice questions

This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.